Discussion this week around Chrome's Sanitizer API, and bypassing firewalls with webhooks and 0days (ModSecurity bypass), and a pre-auth BitBucket RCE.
Links and summaries are available at https://dayzerosec.com/podcast/153.html
[00:00:00] Introduction
[00:00:31] Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
[00:10:31] Breaking Bitbucket: Pre Auth Remote Command Execution [CVE-2022-36804]
[00:16:25] [Chrome] Sanitizer API bypass via prototype pollution
[00:23:02] How we Abused Repository Webhooks to Access Internal CI Systems at Scale
[00:35:03] WAF bypasses via 0days
[00:42:40] Cloning internal Google repos for fun and… info?
[00:43:19] How to turn security research into profit: a CL.0 case study
Pwn2Own Results, Voatz (again), some web-exploits and a code-reuse mitigation
How to Hack a CTF and more (LVI, TRRespass and some web-exploits)
FuzzBench, MediaTek-su, Request Smuggling, and Memory Tagging
kr00k, GhostCat, and more issues from NordVPN, Samsung, OpenSMTPd
A Dark White-Hat hacker? and various vulns ft. Cisco, Periscope, NordVPN and Tesla/EyeQ
A New PWK/OSCP, Election Hacking, Kernel Exploits, and Fuzzing
Hack Twitter, WhatsApp and all your Cisco phones (CDPwn) ft. GhostKnight
OK Google, sudo ./hacktheplanet
Return of the Zombieload, Bezos Hacked, and other exploits
Project Verona, CurveBall, CableHaunt, and RCEs-a-plenty
SHA-mbles, Shitrix, Responsible Disclosure, and wtf is TikTok doing?
First Edge bounty, Hacking Tesla via Wi-Fi, Cisco advisories, and Shadow Clones
PlunderVolt, Real-World Bug Hunting, Presidents Cup CTF, SockPuppet and more
Permanent DoS, HackerOne Hacked, and Wide-OpenBSD
CWE Top 25, Hacking Anti-Viruses and Adversarial Machine Learning Attacks
What does the NSA say?
Election hacking, Kernel Security, MDS Attacks and Github's Security Lab
Rogue Employees, Lasers, Fuzzing, and an iOS Exploit (checkra1n)
A Bit of everything: 0days, Breaches, Lawsuits, Attacking AI, and some insecure
NordVPN Again, Snowden, CPDoS, a PHP-RCE, and some console hacking
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
The Unbelivable Truth - Series 1 - 26 including specials and pilot
Lex Fridman Podcast